Vulnerability Description
Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter in SubmitChat.php and is saved without sanitization and executed whenever a user view the current page game. This vulnerability is fixed by 09dd00e5452e3cd998eb1406a88e5b0fa868e6b4.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Talishar/Talishar/commit/09dd00e5452e3cd998eb1406a88e5b0fa868
- https://github.com/Talishar/Talishar/security/advisories/GHSA-rrr4-h2pc-57g6
FAQ
What is CVE-2026-25144?
CVE-2026-25144 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Talishar is a fan-made Flesh and Blood project. A Stored XSS exists in the chat in-game system. The playerID parameter in SubmitChat.php and is saved without sanitization and executed whenever a user ...
How severe is CVE-2026-25144?
CVE-2026-25144 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25144?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.